GDPR
General Data Protection Regulation (EU) 2016/679
- I. General Data Protection Regulation (GDPR)
- Ch. I — General Provisions
- Art. 1. Subject matter and objectives (1)
- Art. 2. Material scope (4)
- Art. 3. Territorial scope (4)
- Art. 4. Definitions (4)
- Ch. II — Principles
- Art. 5. Principles relating to processing of personal data (12)
- Art. 6. Lawfulness of processing (11)
- Art. 7. Conditions for consent (7)
- Art. 8. Conditions applicable to child's consent in relation to information society services (3)
- Art. 9. Processing of special categories of personal data (13)
- Art. 10. Processing of personal data relating to criminal convictions and offences (2)
- Art. 11. Processing which does not require identification (4)
- Ch. III — Rights of the Data Subject
- Art. 12. Transparent information, communication and modalities for the exercise of the rights of the data subject (16)
- Art. 13. Information to be provided where personal data are collected from the data subject (14)
- Art. 14. Information to be provided where personal data have not been obtained from the data subject (12)
- Art. 15. Right of access by the data subject (15)
- Art. 16. Right to rectification (2)
- Art. 17. Right to erasure (‘right to be forgotten’) (4)
- Art. 18. Right to restriction of processing (6)
- Art. 19. Notification obligation regarding rectification or erasure of personal data or restriction of processing (2)
- Art. 20. Right to data portability (5)
- Art. 21. Right to object (5)
- Art. 22. making, including profiling (10)
- Art. 23. Restrictions (11)
- Ch. IV — Controller and Processor
- Art. 24. Responsibility of the controller (3)
- Art. 25. Data protection by design and by default (7)
- Art. 26. Joint controllers (5)
- Art. 27. Representatives of controllers or processors not established in the Union (3)
- Art. 28. Processor (15)
- Art. 29. Processing under the authority of the controller or processor (2)
- Art. 30. Records of processing activities (17)
- Art. 31. Cooperation with the supervisory authority (3)
- Art. 32. Security of processing (7)
- Art. 33. Notification of a personal data breach to the supervisory authority (10)
- Art. 34. Communication of a personal data breach to the data subject (7)
- Art. 35. Data protection impact assessment (17)
- Art. 36. Prior consultation (7)
- Art. 37. Designation of the data protection officer (6)
- Art. 38. Position of the data protection officer (8)
- Art. 39. Tasks of the data protection officer (6)
- Art. 40. Codes of conduct (15)
- Art. 41. Monitoring of approved codes of conduct (8)
- Art. 42. Certification (7)
- Art. 43. Certification bodies (12)
- Ch. V — Transfers of Personal Data to Third Countries or International Organisations
- Art. 44. General principle for transfers (2)
- Art. 45. Transfers on the basis of an adequacy decision (11)
- Art. 46. Transfers subject to appropriate safeguards (8)
- Art. 47. Binding corporate rules ref
- Art. 48. Transfers or disclosures not authorised by Union law (1)
- Art. 49. Derogations for specific situations (10)
- Art. 50. International cooperation for the protection of personal data (4)
- Ch. VI — Independent Supervisory Authorities
- Art. 51. Supervisory authority (6)
- Art. 52. Independence (9)
- Art. 53. General conditions for the members of the supervisory authority (4)
- Art. 54. Rules on the establishment of the supervisory authority (8)
- Art. 55. Competence (3)
- Art. 56. Competence of the lead supervisory authority (9)
- Art. 57. Tasks (26)
- Art. 58. Powers (14)
- Art. 59. Activity reports (3)
- Ch. VII — Cooperation and Consistency
- Art. 60. Cooperation between the lead supervisory authority and the other supervisory authorities concerned (21)
- Art. 61. Mutual assistance (9)
- Art. 62. Joint operations of supervisory authorities (10)
- Art. 63. Consistency mechanism (2)
- Art. 64. Opinion of the Board (9)
- Art. 65. Dispute resolution by the Board (12)
- Art. 66. Urgency procedure (5)
- Art. 67. Exchange of information (2)
- Art. 68. European Data Protection Board (3)
- Art. 69. Independence (3)
- Art. 70. Tasks of the Board ref
- Art. 71. Reports (7)
- Art. 72. Procedure (3)
- Art. 73. Chair (2)
- Art. 74. Tasks of the Chair (4)
- Art. 75. Secretariat (13)
- Art. 76. Confidentiality (2)
- Ch. VIII — Remedies, Liability and Penalties
- Art. 77. Right to lodge a complaint with a supervisory authority (2)
- Art. 78. Right to an effective judicial remedy against a supervisory authority (4)
- Art. 79. Right to an effective judicial remedy against a controller or processor (3)
- Art. 80. Representation of data subjects (3)
- Art. 81. Suspension of proceedings (3)
- Art. 82. Right to compensation and liability (6)
- Art. 83. General conditions for imposing administrative fines (8)
- Art. 84. Penalties (3)
- Ch. IX — Provisions Relating to Specific Processing Situations
- Art. 85. Processing and freedom of expression and information (4)
- Art. 86. Processing and public access to official documents (2)
- Art. 87. Processing of the national identification number (1)
- Art. 88. Processing in the context of employment (4)
- Art. 89. Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes (5)
- Art. 90. Obligations of secrecy (4)
- Art. 91. Existing data protection rules of churches and religious associations (2)
- Ch. X — Delegated Acts and Implementing Acts
- Art. 92. Exercise of the delegation (3)
- Art. 93. Committee procedure (3)
- Ch. XI — Final Provisions
- Art. 94. Repeal of Directive 95/46/EC (2)
- Art. 95. Relationship with Directive 2002/58/EC (1)
- Art. 96. Relationship with previously concluded Agreements (1)
- Art. 97. Commission reports (6)
- Art. 98. Review of other Union legal acts on data protection (2)
- Art. 99. Entry into force and application (1)
Title I — General Data Protection Regulation (GDPR)
Chapter I — General Provisions
Chapter II — Principles
Chapter III — Rights of the Data Subject
Chapter IV — Controller and Processor
Article 43. Certification bodies
11 obligations
GDPR-43-02
Requirement
Member States must ensure certification body accreditation
Member States must ensure that certification bodies are accredited by either the competent supervisory authority or the
GDPR-43-03
Conformity
Demonstrate independence and expertise for accreditation
Certification bodies must demonstrate their independence and expertise in relation to the subject-matter of the certific
GDPR-43-04
Conformity
Respect approved certification criteria
Certification bodies must undertake to respect the criteria referred to in Article 42(5) and approved by the supervisory
GDPR-43-05
Documentation
Establish certification management procedures
Certification bodies must establish procedures for the issuing, periodic review and withdrawal of data protection certif
GDPR-43-06
Transparency
Establish transparent complaint handling procedures
Certification bodies must establish procedures and structures to handle complaints about infringements of the certificat
GDPR-43-07
Conformity
Demonstrate absence of conflicts of interest
Certification bodies must demonstrate to the satisfaction of the competent supervisory authority that their tasks and du
GDPR-43-08
Conformity
Ensure proper assessment for certification decisions
Certification bodies are responsible for the proper assessment leading to the certification or the withdrawal of such ce
GDPR-43-09
Reporting
Provide reasons for certification decisions to supervisory authorities
Certification bodies must provide the competent supervisory authorities with the reasons for granting or withdrawing the
GDPR-43-10
Transparency
Publish requirements and criteria publicly
Supervisory authorities must make the requirements referred to in paragraph 3 and the criteria referred to in Article 42
GDPR-43-11
Reporting
Transmit requirements and criteria to the Board
Supervisory authorities must transmit the requirements and criteria to the Board.
GDPR-43-12
Monitoring
Revoke accreditation when conditions not met
The competent supervisory authority or national accreditation body must revoke an accreditation of a certification body
Chapter V — Transfers of Personal Data to Third Countries or International Organisations
Article 44. General principle for transfers
2 obligations
GDPR-44-01
Requirement
Comply with Chapter V conditions for third country/international organisation transfers
Controllers and processors must ensure that any transfer of personal data to a third country or international organisati
GDPR-44-02
Data Governance
Ensure protection level is not undermined in international transfers
Controllers and processors must apply all Chapter V provisions in a manner that ensures the level of protection of natur
Article 45. Transfers on the basis of an adequacy decision
11 obligations
GDPR-45-01
Requirement
Commission must assess adequacy considering specific elements
The Commission must take account of rule of law, human rights, legislation, data protection rules, case-law, data subjec
GDPR-45-02
Requirement
Commission must decide on adequacy through implementing acts
The Commission may decide, by means of implementing act, that a third country, territory, specified sectors, or internat
GDPR-45-03
Requirement
Commission must provide periodic review mechanism in implementing acts
The implementing act must provide for a mechanism for periodic review, at least every four years, taking into account al
GDPR-45-04
Requirement
Commission must specify territorial and sectoral application in implementing acts
The implementing act must specify its territorial and sectoral application and, where applicable, identify the superviso
GDPR-45-05
Requirement
Commission must adopt implementing acts under examination procedure
The implementing act must be adopted in accordance with the examination procedure referred to in the regulation.
GDPR-45-06
Monitoring
Commission must monitor developments in third countries on ongoing basis
The Commission must continuously monitor developments in third countries and international organisations that could affe
GDPR-45-07
Requirement
Commission must repeal, amend or suspend inadequate adequacy decisions
The Commission must repeal, amend or suspend adequacy decisions when information reveals that adequate protection is no
GDPR-45-08
Requirement
Commission must adopt suspension acts under examination procedure
Implementing acts that repeal, amend or suspend adequacy decisions must be adopted in accordance with the examination pr
GDPR-45-09
Requirement
Commission must adopt immediately applicable acts on urgent grounds
On duly justified imperative grounds of urgency, the Commission must adopt immediately applicable implementing acts in a
GDPR-45-10
Requirement
Commission must consult with third countries to remedy inadequacy situations
The Commission must enter into consultations with the third country or international organisation with a view to remedyi
GDPR-45-11
Transparency
Commission must publish adequacy status list in Official Journal and website
The Commission must publish in the Official Journal of the European Union and on its website a list of third countries,
Article 46. Transfers subject to appropriate safeguards
1 obligation